SELinux enforcing disallows opening floppy drive in Nautilus

Ron Yorston rmy at tigress.co.uk
Thu Apr 13 17:35:16 UTC 2006


Stephen Smalley <sds at tycho.nsa.gov> wrote:
>Seems like a policy bug (omission of a transition from unconfined_t to
>mount_t) to me.  Otherwise, /etc/mtab is going to lose its type every
>time you run mount/umount from the shell.  Dan?

Just a clarification (or confusion):  it's only umount that causes the
problem.  mount doesn't create a new /etc/mtab file and doesn't change
the context:

   # ls -Z /etc/mtab
   -rw-r--r--  root     root     system_u:object_r:etc_runtime_t  /etc/mtab
   # ls -i /etc/mtab
   33032 /etc/mtab
   # mount /opt
   # ls -Z /etc/mtab
   -rw-r--r--  root     root     system_u:object_r:etc_runtime_t  /etc/mtab
   # ls -i /etc/mtab
   33032 /etc/mtab
   # 

Ron




More information about the fedora-selinux-list mailing list